Junglewise Threat Intelligence

CVE-2026-7461: GO-2026-5353 - Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure in github.com/aws/amazon-ecs-agent

CVE-2026-7461 · Severity: high · CVSS 3.1 · Published 2026-06-25

Technologies: Amazon AWS. Vendors: Amazon Web Services, Amazon, Go.

Executive brief

Amazon ECS is a service used to run and manage containerized applications on AWS. A vulnerability in the ECS agent for Windows allows an attacker to execute commands with full administrative (SYSTEM) privileges on the underlying server. This could lead to a complete takeover of the Windows EC2 instance by providing malicious credentials when configuring file storage volumes.

Technical details

An OS command injection vulnerability exists in the Amazon ECS Agent for Windows during the mounting process of FSx for Windows File Server volumes. The flaw is triggered by providing specially crafted credentials within an ECS task definition. An attacker with the ability to register task definitions or modify referenced secrets can inject arbitrary commands that the agent executes with SYSTEM privileges on the host EC2 instance. The issue affects ECS Agent versions 1.47.0 through 1.102.2 and has been patched in version 1.103.0. Fargate instances are not affected.

Affected products

  • Amazon Web Services ECS Agent for Windows 1.47.0 through 1.102.2

Timeline

  • 2026-04-30: disclosed
  • 2026-04-30: patched: Fixed in ECS agent version 1.103.0

References

Related threats